On 21 September 2026 a BYD Shark 6 changes hands remotely
On 21 September 2026 ABC News published the results of a test carried out on a country road near Canberra. A security expert took remote control of a BYD Shark 6 while the journalist was behind the wheel. The Australian broadcaster's report[1] describes headlights switched off mid-corner, doors locked with the reporter inside, wipers and washers triggered from a distance.
Dan Hreszczuk, co-founder of Fortify Labs in Canberra, had the vehicle at his disposal for two weeks before the demonstration.
His verdict fits in one line: "It was easier than we expected." The access point he exploited had no password.
From that opening the analyst reconstructed the programs governing each on-board function. Connected Chinese cars reach the European market with the same underlying architecture: software at the centre, continuous updates, remote control by the manufacturer.
Modern vehicles, electric and hybrid ones in particular, run on code. The manufacturer retains the ability to change, update and govern the vehicle after the sale. In BYD's case that software answers to entities based in China.
Why the Australian test weighs on market numbers
The same report carries one figure for context. In Australia this year, electric and plug-in hybrid vehicles account for almost a third of new car sales.
More than half of those sales carry a Chinese badge.
Scale matters more than the single vehicle that was breached. A corporate fleet buys in batches, with a single model repeated dozens of times. A design weakness then becomes a weakness across the entire fleet.
Security Affairs picked up the case on 21 September 2026[2], with the technical detail of the intrusion. Pierluigi Paganini's outlet places the episode in the wider category of connected vehicle risk.
On-board sensors, cameras and microphones collect and transmit high volumes of data. The experts quoted by the broadcaster note that Chinese national security laws can oblige companies to cooperate with the authorities.
The Dahua cameras on board Leapmotor vehicles
On 21 September 2026 the same broadcaster published a second finding. On board some Leapmotor vehicles Dahua cameras were found[3], a brand banned from public buildings in Australia.
The ban covers state-owned property. A company vehicle crosses those same perimeters every day.
The compliance question starts here: a component excluded from a physical perimeter re-enters that perimeter fitted to a car. The distinction between fixed hardware and mobile hardware holds up poorly in inventory terms. An asset register that logs building cameras and ignores in-vehicle ones describes half the reality.
For anyone governing risk, the issue is supply traceability. Knowing which camera brand travels on which model belongs in purchase due diligence.
The check concerns the tender specification and the vehicle's technical datasheet. Buyers ordering from a catalogue rarely receive the bill of electronic components.
9 September 2026: US carmakers call for a ban
On 9 September 2026 US carmakers asked Congress to ban Chinese-origin connected vehicles, software and hardware. The request[4] arrived as the session was closing.
The scope set out covers the whole chain: finished vehicle, components and code.
The US jurisdiction proceeds by origin-based bans. The European Union proceeds through type-approval obligations and data access rights. The two routes lead to different documentary duties over the same fleet.
A group with vehicles in both areas runs two parallel regimes. A purchasing policy that works in Europe remains exposed to a US restriction on origin.
The governance signal is the shared direction of travel: the origin of software is entering the regulatory substance. For decades vehicle compliance concerned emissions and passive safety. Today it includes the chain of control over the code on board.
The European rule on car data: the Data Act
Regulation (EU) 2023/2854, the Data Act, has applied since 12 September 2025. The text[5] governs access to data generated by connected products, cars included.
The framework gives the product's user the right to access the data generated by its use. It also provides for the option of sharing that data with third parties chosen by the user. The manufacturer remains obliged to make that data available.
The jurisdiction is the European Union. The rule has been in application for over a year.
For a fleet the operational consequence is concrete. The manager can ask the manufacturer for vehicle data and route it to an independent maintenance operator. The supply contract becomes the place where that right is actually exercised.
The regulation governs access to data. The security of the channel and the identity of whoever gets in remain the subject of other instruments.
Cyber type-approval: UNECE regulations R155 and R156
UNECE regulations R155 and R156 cover the management of cybersecurity and of software updates. They have been mandatory for new vehicles registered in the European Union since July 2024.
R155 requires the manufacturer to hold a certified cybersecurity management system. R156 requires a software update management system. Type-approval depends on both.
The European framework therefore works along two distinct axes: who accesses the data, and how the vehicle is protected and updated. The Australian case concerns a market with rules of its own.
That distinction matters for a European fleet. A model sold in Australia and the same model sold in Europe may carry different software configurations. The check concerns the certificate for the vehicle actually delivered.
The document to request from the supplier has a precise name: the type-approval extract with the R155 and R156 references. A tender specification that cites those two numbers shifts the burden of proof onto the seller.
Three decisions for the board
The three questions that follow belong to the General Counsel, the Chief Risk Officer and the audit and risk committee.
1. Which role, by name and in writing, answers for on-board data
The Data Act assigns rights to the user of the connected product. For a company that user is an entity, so ownership must be assigned to a specific person before the vehicles are delivered. A framework without a name in writing produces documentation instead of governance.
2. Which clause covers the manufacturer's remote access
The purchase or leasing contract defines which functions the supplier can activate remotely. The Australian test concerns access obtained by a third party; the clause concerns the manufacturer's legitimate access. Separating the two levels makes it possible to write verifiable obligations.
3. What disclosure the audit committee needs
A connected vehicle fleet is at once a data processing perimeter and a security perimeter. The committee receives the inventory of models, the origin of critical components and the status of R155 and R156 type-approvals. A reasonable frequency matches the one already used for other IT assets.
Regulatory horizon and Monday morning
Current state: the Data Act has applied since 12 September 2025; R155 and R156 apply to new vehicles in the EU from July 2024. Both instruments are in force today.
The US front remains an industry request filed on 9 September 2026, a proposal in search of a legislative vehicle.
The head of a European fleet has three immediate actions. The first: pull from the system the list of connected models in service, with make and year. The second: ask the supplier for the type-approval extract with the R155 and R156 references.
The third concerns data: a formal request to the manufacturer about the flows generated by the vehicles, grounded in Regulation 2023/2854. Three emails were enough in a single morning of work.
The question about one model's vulnerability has been answered. The question of who governs the software across an entire fleet remains open.
This article was written by an AI editorial author under human supervision, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- The Australian broadcaster's report (abc.net.au)
- Security Affairs picked up the case on 21 September 2026 (securityaffairs.com)
- Dahua cameras were found (abc.net.au)
- The request (collisionweek.com)
- The text (digital-strategy.ec.europa.eu)